Bug #65069 [Ana->Csd]: GlobIterator fails to access files inside an open_basedir restricted dir

From: Date: Thu, 28 Jul 2022 10:45:33 +0000
Subject: Bug #65069 [Ana->Csd]: GlobIterator fails to access files inside an open_basedir restricted dir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242048@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65069&edit=1 ID: 65069 Updated by: git@php.net Reported by: seld@php.net Summary: GlobIterator fails to access files inside an open_basedir restricted dir -Status: Analyzed +Status: Closed Type: Bug Package: SPL related Operating System: Windows7 PHP Version: 5.5.0RC3 Block user comment: N Private report: N New Comment: Automatic comment on behalf of bukka Revision: https://github.com/php/php-src/commit/1a9e6895f1d203f38655b52d5b6b823be7d14cbd Log: Fix #65069: GlobIterator incorrect handling of open_basedir check Previous Comments: ------------------------------------------------------------------------ [2022-07-26 11:54:25] bukka@php.net The following pull request has been associated: Patch Name: Fix #65069: GlobIterator incorrect handling of open_basedir check On GitHub: https://github.com/php/php-src/pull/9120 Patch: https://github.com/php/php-src/pull/9120.patch ------------------------------------------------------------------------ [2022-01-04 17:49:17] epinci at tiscali dot it Hello, I'm still hitting this one on Windows with PHP 7.4.27 and 8.1.1. Has this ever been fixed? Thank you. ------------------------------------------------------------------------ [2021-05-20 15:43:31] cmb@php.net Related To: Bug #74016 ------------------------------------------------------------------------ [2013-06-21 15:33:28] ab@php.net Ah, just to mention, GlobIterator is the same as DirectoryIterator('glob://....') ... so that on is broken too. ------------------------------------------------------------------------ [2013-06-21 15:15:25] ab@php.net Ok, the issue is much more complicated than it looks. This is a very tricky case because the glob pattern check against the open_basedir value obviously makes no sense. The implementation of the glob function is simply to - expand the pattern - iterate checking for basedir restriction on every item - discard result and return false if one of them was not within basedir What's going on in GlobIterator is to check the basedir against the pattern in __construct, that obviously will never work properly. Also, glob extends Filesystem iterator, only __construct() and count() methods are implemented. Two solutions come in my mind: - do the same teh glob() function does, do the work in construct and throw exception if one of the paths isn't allowed (but that means doing the work twice), so no go - impement the necessary methods in GlobIterator, like current(), next(), etc. .. this seems more plausible, however the situation where a value isn't within basedir, what would for instance current() return? false? ... Looks like a big behavior change anyway. Any ideas for a better fix? Thanks ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=65069 -- Edit this bug report at https://bugs.php.net/bug.php?id=65069&edit=1

« previous php.bugs (#242048) next »